ExecuteMalware

2021-02-17 Hancitor IOCs

Feb 17th, 2021 (edited)
4,484
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.52 KB | None | 0 0
  1. THREAT IDENTIFICATION: HANCITOR
  2.  
  3. HANCITOR BUILD
  4. BUILD=1702_pro23
  5.  
  6. SUBJECTS OBSERVED
  7. You got invoice from DocuSign Electronic Signature Service
  8. You got notification from DocuSign Signature Service
  9. You received invoice from DocuSign Electronic Service
  10. You received invoice from DocuSign Service
  11. You received notification from DocuSign Electronic Service
  12. You received notification from DocuSign Electronic Signature Service
  13. You received notification from DocuSign Signature Service
  14.  
  15. SENDERS OBSERVED
  16.  
  17. MALDOC LANDING PAGE URLS
  18. https://docs.google.com/document/d/e/2PACX-1vQgIfA0Eba71P-4GAbtR9i4UzopM0AVx7PVI7nrYF65fUrmkjXuROsxRlQ1FVz6uOAa_9mgcwBSpEYX/pub
  19. https://docs.google.com/document/d/e/2PACX-1vRdIMUUkcPV2W_XHw5WBZSOGyvwkzjZ_G15YWvoTmRJh-IR4dOQKSnTxNDTv3W57vSzTRTyWAbsrWQU/pub
  20. https://docs.google.com/document/d/e/2PACX-1vSdAF6b9dDsWkDaM--xHUM-KzMQjYprAT0P6zhLpb_CGC-eE05dcTdX5tm5DVumDRvzCJ7XwB_XsPTq/pub
  21. https://docs.google.com/document/d/e/2PACX-1vT10dUghgCUkjXirdGrkZtDHfU2OFKPTpous1hQPbuH58PWWi_xmweyAyzolI6Y-evxcqrbKnN1Mo90/pub
  22. https://docs.google.com/document/d/e/2PACX-1vTcmrejDN5ihjM_Kc1Usu30hLGiEX1f932P2DEt_x6lQxE11EJm1o2E3sGFpUNanJcA3gsQj91tOpNZ/pub
  23. https://docs.google.com/document/d/e/2PACX-1vTE15GfZYtu2PXt0P_LXK4OXELVVWTVFzrLWOtU6Asrl0lHdgR_8JTwSc7-nSvk7m0yudTNGzVpqGU1/pub
  24. https://docs.google.com/document/d/e/2PACX-1vTqMpUzmOn4a2pgQDMYRK_CT8UUYeo0ePFKi2sPvFbHhaGvk4zrwW-RO_gb_WhzUxmJ91elxpJpKeXU/pub
  25.  
  26. MALDOC DISTRIBUTION URLS
  27. http://somdeeppalace.com/slickness.php
  28. https://buahpinggang.my/parma.php
  29. https://jayins.com/disquieting.php
  30. https://pepselectricailservice.co.uk/archiver.php
  31.  
  32. somdeeppalace.com
  33. buahpinggang.my
  34. jayins.com
  35. pepselectricailservice.co.uk
  36.  
  37. HANCITOR MALDOC FILE HASHES
  38. 0b5f29fb9e3c4b2ef56af61b6046115d
  39. 1283f5be56f3834d8effcb6182d01dfa
  40. 6339d90f60316aa4df36f4dfd085d320
  41. ef0e5920daa89ba15bac2357bee2b502
  42.  
  43. HANCITOR PAYLOAD FILE HASH
  44. W0rd.dll
  45. 532a355471de8f834460e026ccd65150
  46.  
  47. HANCITOR C2
  48. http://hatuderefer.com/8/forum.php
  49.  
  50. FICKER STEALER PAYLOAD URLS
  51. http://belcineloweek.ru/6sufiuerfdvc.exe
  52.  
  53. FICKER STEALER FILE HASH
  54. 6sufiuerfdvc.exe
  55. 77be0dd6570301acac3634801676b5d7
  56.  
  57. FICKER STEALER C2
  58. http://sweyblidian.com
  59.  
  60. Post .doc file download phishing page (M&T Bank):
  61. https://webinfoplus.xn--mndtbnk-9m4ce.com/cashplus
  62.  
Add Comment
Please, Sign In to add comment